- What: Cybersecurity M&A activity in August 2026
- Impact: Multiple companies announced acquisitions
Funding/M&A Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa. By Eduard Kovacs | September 10, 2026 (12:14 PM ET) Flipboard Reddit Whatsapp Whatsapp Email Thirty-three cybersecurity-related merger and acquisition (M&A) deals were announced in August 2026. For a detailed view of the more than 420 acquisitions announced in 2025, check out SecurityWeek’s annual M&A report . Here are some of the most important cybersecurity M&A deals announced in August 2026: Brinqa acquires PlexTrac Continuous Threat Exposure Management (CTEM) firm Brinqa has acquired PlexTrac, a penetration testing workflow and reporting vendor. The acquisition integrates PlexTrac’s offensive security validation into Brinqa’s CTEM platform to verify remediation efforts. Cribl acquires Radiant Security Advertisement. Scroll to continue reading. Cribl has acquired technology assets and IP from San Francisco-based Radiant Security, an AI-native SOC startup. Cribl will integrate Radiant’s autonomous alert triage and incident response capabilities directly into its telemetry data platform. Datavault AI to acquire CyberCatch Data monetization, credentialing, digital engagement, and RWA tokenization solutions provider Datavault AI has announced a definitive all-cash agreement to acquire San Diego-based CyberCatch for $94.5 million. The acquisition integrates CyberCatch’s continuous compliance platform and post-quantum encryption technology into Datavault AI’s platform. Deel acquires Clarity Deel has acquired Israel-based Clarity, an AI cybersecurity company specializing in deepfake detection and identity verification. Financial terms were not officially disclosed, but the deal is reportedly valued at $40-50 million. Deel will integrate Clarity’s technology to prevent identity fraud and detect deepfakes during remote workforce hiring. Echo acquires Minimus Echo has acquired the technology assets and enterprise customer contracts of Tel Aviv-based hardened container image provider Minimus in an all-cash deal following Minimus’s operational wind-down . Financial terms were estimated at a few million dollars. The deal enables Echo to broaden distro support, expand integrations, and strengthen the proprietary agents powering its software factory. Fortinet acquires Virtue AI Fortinet announced the acquisition of AI security company Virtue AI. Fortinet said the acquisition will help it enhance its AI security offering, including for models, applications, and agentic systems. Fortinet will leverage Virtue’s agentic system red teaming, agent protection and governance, continuous AI validation, and real-time guardrail capabilities. Kiteworks acquires WAMNET Kiteworks announced moving into Japan through its seventh acquisition in less than five years. The company has acquired WAMNET Japan K.K., a secure data transfer and file-sharing provider. The deal extends Kiteworks’ private content network (PCN) strategy — unifying file sharing, managed file transfer, email, APIs, and web forms under one governed platform — into a new geography, with WAMNET’s existing contracts, pricing, and support staying in place and customer data remaining hosted in Japan. Munich Re acquires At-Bay German reinsurance giant Munich Re has agreed to acquire California-based cyber insurtech At-Bay for $575 million. At-Bay will join Munich Re’s HSB unit, combining continuous risk mitigation and MDR services with global insurance coverage. Palo Alto Networks acquires Console Palo Alto Networks has acquired Console, an AI-native platform that helps organizations build agentic workflows and automate operational tasks using natural language. The cybersecurity giant said Console will deepen the agentic capabilities of its Cortex platform, allowing security teams to investigate signals, prioritize work, and automatically take action across enterprise environments. Visa to acquire BioCatch Visa is buying fraud prevention company BioCatch for $2.4 billion in cash as the payments giant looks to expand its cybersecurity and financial crime detection capabilities. The acquisition will add BioCatch’s behavioral and device intelligence to Visa’s existing portfolio of cyber, fraud, risk and security products. Other cybersecurity M&A deals announced in August 2026: Ampcus acquires SmarterD Anaconda acquires Enkrypt Athena Agentic acquires Maxxsure and Omni Cyber Solutions AXA XL to acquire S-RM BlueAlly acquires GigaNetworks Bridgepoint acquires majority stake in Lansweeper Cycurion acquires Kustom Entertainment ePlus acquires Daymark Guardsix acquires Logmanager H.I.G. Capital sells ECI to Wind Point Partners Image Solutions acquires Romeo Computer Company Integrity360 acquires CyberIAM LG Uplus acquires Pago Networks Logicalis US acquires Loial NetApp acquires JetStream Software New Charter acquires CyberTrust IT Solutions Nexus IT acquires Loyal IT Privacy Bee acquires EraseMe.app Redsquid acquires ARK ICT SEPPmail acquires CyberPilot Systematic Growth acquires 4Secure Terma to acquire Dencrypt A/S Universal Digital Inc. to acquire PQCEE Related : Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 Related : Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild PaperCut Exploitation Escalates to Active Intrusions Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit Latest News Anthropic Researcher Resigns With Warning About the Dangers of AI Development Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation Critical NetScaler Vulnerability Exploited in Attacks Widened Scan Turns Up Fourth Rogue Claude Cyber Incident 4.1 Million Impacted by AdaptHealth Data Breach Organizations Warned of Cisco Secure FMC Exploitation Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the Move Amazon has elected Kevin Mandia to its Board of Directors. Gigamon has named Grant Yacomeni as Chief Information Security Officer. SSH Communications Security has appointed Lars Bell as Chief Executive Officer. More People On The Move Expert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email